CVE-2025-2280

HIGH

Devolutions Server < 2024.3.6.0 - Authenticated Browser Extension Restriction Bypass

Title source: llm
STIX 2.1

Description

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
devolutions/devolutions_server < 2024.3.6.0
Published Mar 13, 2025
Tracked Since Feb 18, 2026